CRITICAL🇵🇱 Wersja polska

CVE-2026-4692

CVSS 10.0v3.1pub. 2026-03-24upd. 2026-06-30

Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

🤖 AI Analysis
How it works

The bug is located in the Responsive Design Mode component, a developer tool used to preview websites at various screen resolutions. The vulnerability allows an attacker to escape the isolated execution environment (sandbox), which normally restricts the capabilities of malicious code. The detailed technical mechanism has not been disclosed by the manufacturer (CWE: NVD-CWE-noinfo), however, the maximum CVSS vector indicates that the attack is possible remotely, without authentication and without user interaction, and the impact extends beyond the originally isolated application context.

Impact

An attacker can gain full control over the victim's system — including access to sensitive data, ability to modify files, and disruption of system operation — by breaking out of the isolation mechanisms of the browser or mail client.

Mitigation & patch

The software must be updated immediately to the following versions: Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, or Thunderbird 140.9, in which the vulnerability has been patched by the manufacturer.

Who is affected

Mozilla Firefox versions before 149, Mozilla Firefox ESR versions before 115.34 and before 140.9, Mozilla Thunderbird versions before 149 and before 140.9.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Mozilla Firefox

    APP
    Mozilla
    < 115.34.0< 149.0128.0 – 140.9.0 (excl.)
  • Mozilla Thunderbird

    APP
    Mozilla
    < 140.9.0< 149.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-9680CRITICAL9.8⚠ KEVPL ✓same product

Use-after-free w Animation timelines Firefox/Thunderbird — RCE

CVE-2022-26486CRITICAL9.6⚠ KEVPL ✓same product

Use-after-free w WebGPU IPC framework Mozilla — sandbox escape

CVE-2019-11708CRITICAL10.0⚠ KEVPL ✓same product

Mozilla Firefox/Thunderbird: przełamanie sandbox przez IPC Prompt:Open

CVE-2010-3765CRITICAL9.8⚠ KEVPL ✓same product

RCE w Mozilla Firefox przez błąd nsCSSFrameConstructor::ContentAppended

CVE-2026-74936CRITICAL9.8same product

Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ...